About

About Ardent Infosec

I get dropped in when things are broken—and I fix them

I have spent 15 years as a fractional and acting CISO for healthcare organizations, most often stepping in after a breach, a leadership departure, or an OCR data request forces the issue. My job is to quickly assess an unfamiliar environment, set priorities, and build a security program that holds up under regulatory scrutiny.

Cyber insurers and breach-response law firms refer clients to me because of my track record: across my entire client history, not one organization has received an OCR fine following my involvement. None have appeared on the HHS “Wall of Shame” a second time after corrective action.

I adapt to each client’s environment, resource constraints, and risk tolerance—no one-size-fits-all binders, no bias imported from other organizations.

Services

Breach Response & OCR

Rapid stabilization and corrective action for HIPAA breaches. Includes OCR data request responses, forensics coordination, and remediation plans executed under mandatory reporting timelines.

Fractional & Acting CISO

Embedded security leadership for organizations without a full-time CISO. Covers team management, executive briefings, vendor oversight, policy governance, and ongoing operating cadence.

Risk Assessments

NIST CSF and NIST SP 800-53 aligned risk analyses mapped to your actual environment. Findings are prioritized and delivered in plain language, not generic templates or compliance checklists.

Policy & GRC Programs

Security policy suites, standards, procedures, and GRC platform builds grounded in real operational constraints. Includes charters, documentation cadences, and the governance rhythms that keep programs audit-ready year-round.

Vendor Risk

Risk-tiered vendor programs covering onboarding, periodic reevaluation, and offboarding. Includes evidence-based reviews, vulnerability scanning prior to network access, and standardized procedures that maintain an assurance posture between audits.

Security Awareness

Targeted phishing simulations and training programs designed for behavior change, not checkbox compliance. Includes gamified engagement, newsletter content, and materials tailored to your workforce and threat landscape.

Credentials

CISSP certification
CCSP certification
CISM certification
CIPP/US certification
GPEN certification
GCIH certification
GCIA certification
GWAPT certification

Active Certifications

  • CISSP — ISC2
  • CCSP — ISC2
  • CISM — ISACA
  • CIPP/US — IAPP
  • GPEN — GIAC/SANS
  • GCIH — GIAC/SANS
  • GCIA — GIAC/SANS
  • GWAPT — GIAC/SANS

Education & Recognition

  • M.S. Cybersecurity & Information Assurance — Western Governors University
  • B.S. Applied Cybersecurity — SANS Technology Institute
  • SANS Advisory Board Member
  • FEMA IS-100 & IS-700 Certificates

Publications & Service

  • Coauthored “HIPAA Security: Compliance and Case Studies” — Texas Medical Association
  • Published in 2600: The Hacker Quarterly
  • ISC2 Subject Matter Expert — HCISPP exam development
  • SANS Internet Storm Center contributor — honeypot operations & threat analysis

Get in Touch

Work with me

Available for fractional CISO engagements, breach response, risk assessments, and GRC program work. I typically respond within one business day.

contact@ardentinfosec.com

No social media presence by design. References available upon request.